Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Plex patched multiple undisclosed flaws in Media Server 1.43.3 and Desktop 1.115.0, urging all users to update immediately.
Plex released fixes in Plex Media Server 1.43.3 and Plex Desktop 1.115.0 for multiple undisclosed security flaws, with CVE identifiers requested and details not yet published. Censys data shows more than 360,000 devices expose the Plex Media Server web interface. Past Plex flaws saw real exploitation, including CVE-2020-5741 (CVSS 7.2), used to implant a keylogger on a LastPass employee's home computer during the 2022 breach, and CVE-2025-34158 (CVSS 8.5), an authentication bug patched in August 2025.
- Fixes shipped in Plex Media Server 1.43.3 and Desktop 1.115.0
- CVE identifiers requested; flaw details still undisclosed
- Over 360,000 Plex Media Server web interfaces exposed per Censys
- Plex bug CVE-2020-5741 was used in the 2022 LastPass breach
- NAS users may need to install updated packages manually
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-5741 | Authenticated Deserialization RCE in Plex Media Server on Windows CVE-2020-5741 is a deserialization-of-untrusted-data flaw (CWE-502) in Plex Media Server on Windows: the server deserializes a serialized Python (pickle) object supplied over the network without adequate validation. A remote attacker who has already authenticated with high-privilege credentials to the server can submit a maliciously crafted serialized object, causing the server to execute arbitrary Python code upon deserialization. Successful exploitation yields code execution in the context of the Plex Media Server process on the Windows host, exposing that machine's data and credentials and, as demonstrated in the 2022 LastPass breach, potentially providing a foothold into connected environments. Windows installations running a release without the vendor's 2020 security fix are affected; Linux/NAS deployments are outside the described scope of this flaw. Exploitation is confirmed: it carries a 72.9% EPSS probability (99th percentile), has public PoC exploits (Tenable TRA-2020-32 and a PacketStorm write-up), was added to CISA's KEV catalog on 2023-03-10, and is publicly linked to the LastPass breach, where an unpatched Plex Media Server on an employee's PC was the entry point. Do: Update Plex Media Server on every Windows host to the latest release per vendor instructions (a fix shipped in 2020), prioritizing machines used by staff with privileged or remote access, and verify versions by inventory since unpatched instances remain common. Because exploitation requires authenticated high-privilege Plex credentials, review and rotate those credentials and check affected hosts for indicators of compromise such as unexpected processes or lateral movement, as demonstrated in the LastPass incident. | 7.2 | 73% | KEV PoC ×2 |
| large≈300,000+ exposed/vulnerable Plex Media Server instances, with the Windows subset affected by this flaw | |
| CVE-2025-34158 | Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the credentials of the server owner (and a /api/resources call reveals other servers accessible by that server owner). NVD description · AI analysis pending | 8.5 | <1% | — | — |
Full article377 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 04, 2026Vulnerability / Network Security
Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws.
The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them.
"We recommend all server owners and Desktop users update to the latest version as soon as possible," Plex said in an announcement this week. "If you're running Plex Media Server on a NAS device, the updated version may not be available in their package manager yet, but you can install the package manually."
In August 2025, Plex addressed a high-severity security flaw (CVE-2025-34158, CVSS score: 8.5), an authentication bug that stemmed from the "/myplex/account" endpoint incorrectly exposing the server owner's account details, including their administrative access token, even when accessed by any authenticated non-owner or lower-privileged user.
Additionally, a subsequent "/api/resources" API call can be used to reveal other servers accessible by that server owner, potentially exposing the owner's entire Plex infrastructure to unauthorized access. The combination of the two API calls creates an exploit chain that can lead to infrastructure discovery.
Data from Censys shows that there are more than 360,000 devices exposing the Plex Media Server web interface, although it's worth noting that not all of them are vulnerable.
Vulnerabilities in Plex Media Server have been exploited by threat actors from time to time. In February 2021, Plex released a security update to resolve an issue that allowed attackers to cause an affected server to "reflect" UDP packets in order to increase the volume of a denial-of-service (DoS) attack against another server.
The hotfix (Plex Media Server v1.21.3.4014 or newer) ensures that the server will only respond to UDP requests from the local network (LAN) and not the public internet (WAN).
Notably, the August 2022 breach of LastPass was driven by attackers implanting keylogger malware on an employee's home computer after compromising it through a Plex Media Server vulnerability (CVE-2020-5741, CVSS score: 7.2).
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/09/plex-urges-immediate-updates-after.html